CVE-2024-5148: Gnome-remote-desktop: inadequate validation of session agents using d-bus methods may expose rdp tls certificate
A flaw was found in the gnome-remote-desktop package. The gnome-remote-desktop system daemon performs inadequate validation of session agents using D-Bus methods related to transitioning a client connection from the login screen to the user session. As a result, the system RDP TLS certificate and key can be exposed to unauthorized users. This flaw allows a malicious user on the system to take control of the RDP client connection during the login screen-to-user session transition.
Other sources
Description: gnome-remote-desktop system daemon does inadequate validation of session agents using D-Bus methods related to transitioning a client connection from the login screen to the user session. As a result, the system RDP TLS certificate and key can be exposed to unauthorized users. Furthermore, it may be possible for a malicious user on the system to take control of the RDP client connection during the login screen to user session transition.
Affected version: 46.alpha through 46.1
Fixed version: 46.2 (forthcoming)
Reference: https://gitlab.gnome.org/GNOME/gnome-remote-desktop/-/issues/196
— Red Hat
gnome-remote-desktop fails to validate up front that the caller of methods on handover objects matches the user associated with the session involved with the handover process.
— Ubuntu
This CVE was automatically created from a reference found in an email or other text. If you are reading this, then this CVE entry is probably erroneous, since this text should be replaced by the official CVE description automatically.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-5148?
CVE-2024-5148 has been rated as a medium severity vulnerability due to inadequate validation of session agents.
How do I fix CVE-2024-5148?
To fix CVE-2024-5148, upgrade the gnome-remote-desktop package to version 46.2 or later.
What systems are affected by CVE-2024-5148?
CVE-2024-5148 affects the gnome-remote-desktop package on Ubuntu, Debian, and Red Hat systems.
Who is responsible for managing the gnome-remote-desktop security updates related to CVE-2024-5148?
Security updates for gnome-remote-desktop related to CVE-2024-5148 are managed by the respective maintainers of Ubuntu, Debian, and Red Hat.
What consequences can arise from not addressing CVE-2024-5148?
Failing to address CVE-2024-5148 can lead to unauthorized access or exploitation of remote desktop sessions.